The question is rarely "who is best" — it is "what does this organisation need for the next eighteen months, and what happens after that". All three models work; they fail differently, and the failure modes are predictable enough to plan around.
The three models
| Fractional / vCISO | Consultancy | In-house hire | |
|---|---|---|---|
| Typical use | Ongoing leadership, part-time | Defined project, fixed scope | Permanent capability |
| Speed to start | Days to weeks | Weeks | Two to six months to hire |
| Cost shape | Monthly retainer | Project fee | Salary + overhead, permanent |
| Breadth | Broad, senior, shallow hours | Deep in their specialism | Whatever one person knows |
| Main failure mode | Too few hours to execute | Leaves, taking the knowledge | Wrong hire is expensive and slow to unwind |
When a vCISO fits
Best where you need judgement more than hours: setting direction, choosing frameworks, sizing risk, talking to boards and customers, and supervising people who do the work. Typical fit is a company under a few hundred staff with a real obligation — a certification, a regulator, an enterprise customer — but not enough recurring work to justify a full-time senior salary.
The failure mode is specific and common: a vCISO cannot also be your execution capacity. Two days a month buys direction, not evidence collection, ticket chasing or policy writing. Organisations that buy leadership and expect delivery end up with excellent advice and an unmoved programme.
The fix is to pair the vCISO with either an internal analyst or automation that removes the recurring work. That combination — senior direction plus tooling — is usually cheaper and faster than a full-time hire at the same stage.
Give whoever leads it a system to work in
GRC Copilot carries the control library, evidence and recurring tasks — so fractional leadership spends its hours on decisions instead of chasing spreadsheets.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
When a consultancy fits
Best for bounded, expertise-heavy work with a clear end: a first certification where nobody internally knows what "good" looks like, a specific technical assessment, a regulatory response, or surge capacity around an audit.
Two cautions worth stating plainly. First, independence — a firm cannot both implement your management system and certify it, and using the same firm for consulting and audit invites questions even where it is permitted. Second, knowledge transfer: an ISMS built entirely by a consultancy, documented in their templates and understood by nobody internally, tends to fail at the first surveillance visit after they leave. Make handover an explicit deliverable with named internal owners, not an afterthought.
When to hire
Hire when the work is continuous rather than project-shaped, when security is core to your product or your buyers, when a regulator expects an accountable named individual, or when you have enough recurring volume that fractional hours no longer cover it. Questionnaire load and evidence work scale with revenue rather than risk, and that is usually the signal.
The first hire is often better as a capable generalist who will build and operate than as a big-title strategist — direction can be bought fractionally; execution generally cannot.
The question that actually decides it
Accountability cannot be outsourced. Regulators, auditors and customers expect an accountable individual inside your organisation, and contractual or regulatory duties remain yours whoever performs the work.
So the real test is: who inside the company owns the outcome? A vCISO or consultancy can hold the expertise and even the day-to-day, but someone internal must own the risk decisions and be able to answer for them. If nobody can, you have bought activity rather than assurance.
The usual progression
Most companies move through the models rather than choosing one forever: consultancy for the first certification, a vCISO to run the programme afterwards, an internal analyst as evidence and questionnaire volume grows, then a full-time lead once security becomes continuous. Switching is normal and expected — plan the handover points rather than treating each change as a failure of the last arrangement.
Frequently asked questions
How many days a month does a vCISO need?
Commonly two to five, depending on obligations and how much internal execution capacity exists. If you are relying on them to do the work as well as direct it, the number is much higher — or the model is wrong.
Can the same firm consult and audit?
Not for the same management system. Certification bodies must be independent of the implementation, and blurring it undermines the certificate's value.
Is a vCISO acceptable to regulators and customers?
Generally yes, provided accountability is clear and an internal owner exists. Some regulated sectors expect a named, resident individual — check before assuming.
What is the biggest risk with outsourcing?
A programme nobody internally understands. Insist on knowledge transfer, internal control owners, and documentation in your systems rather than the provider's.
Key takeaways
- Buy judgement fractionally; execution capacity rarely comes with it.
- Consultancies fit bounded projects — make knowledge transfer a deliverable.
- Hire when the work becomes continuous, and prefer a builder over a title.
- Accountability stays internal whatever model you choose.